New variant of Android ransomware "Fake Defender" surfaces

Share this article:

Researchers believe a spam campaign is spreading a new variant of mobile ransomware.

Malware called “Fake Defender,” was first discovered in June, but security firm Symantec has now detected that the malware's authors are using a different ruse to target Android users, primarily in Russia.

The malicious application, detected as fakedefender.B., is designed to look like the official application for an adult video website, a Wednesday blog post by Symantec researcher Roberto Sponchioni said. But once users install the app, messages warn them to run an antivirus scan that is supposedly Avast AV.  

Once the spurious AV scan is finished, the user's phone is locked for their “protection,” and the app asks for a ransom payment of $100 via a prepaid MoneyPak card.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.